SlideShare a Scribd company logo
1 of 17
DRP/ECP
Disaster Recovery Plan / Enterprise
Continuity Plan
Marcelo Silva
Agenda
īŽ
īŽ
īŽ
īŽ
īŽ

īŽ
īŽ

Introduction
Roles of DRP/ECP
The 6 Resilience Layers
Training for the DRP team
Choosing outside expertise to assist with
development of a DRP
Developing a DRP/ECP awareness campaign
Implementing a DRP/ECP awareness campaign
Introduction
īŽ
īŽ
īŽ
īŽ

Why DRP/ECP?
Benefits of a DRP/ECP
Three vital Ingredients of a successful DRP/ECP
Defensive Posture / Offensive Posture
Roles of DRP/ECP
īŽ
īŽ
īŽ
īŽ
īŽ
īŽ
īŽ

Emergency Management team (EMT)
Damage Assessment Team
Restoration Team
Operations Team
Customer Support Team
Salvage/Reclamation Team
Administrative Support Team
The 6 Resilience Layers
1.
2.
3.
4.
5.
6.

Strategy
Organization
Business and IT Processes
Data and Applications
Technology
Facilities and security
The 6 Resilience Layers
1.Strategy
Strategy is the first layer to be discussed
On this layer, the below components will be
assessed and examined:
īŽ Vulnerabilities
īŽ Risks
īŽ Competitive edge
īŽ baseline organizational culture
The 6 Resilience Layers
2.Organization
īŽ
īŽ
īŽ
īŽ
īŽ

Executive sponsor
Roles, Responsibilities and Accountabilities
Well defined communication protocol
Cross-line-of-business linkage
Skills that are critical to the company
The 6 Resilience Layers
3.Business and IT Process
A successful plan requires identify:
īŽ

īŽ

īŽ

īŽ

īŽ

The minimum required functionalities during disruptive
events
Alternate process/procedure that will allow operations to
continue
Processes to achieve better workload balance

All processes and the contingency plan must be
clear to all organization’s stakeholders
Business processes that support Virtual, flexible and
distributed workplaces
The 6 Resilience Layers
4.Data and Applications
īŽ
īŽ
īŽ
īŽ

Good, valuable and reliable information
Data and Application diversification
Architectures standardization
Ensure performance, availability and scalability
The 6 Resilience Layers
5.Technology
Technology components when
planning resiliency:
īŽ Hardware architecture
īŽ System software
īŽ Middleware
īŽ Networks
īŽ Security Solutions

Levels of availability that
should be aligned to the
resiliency objectives:
ī‚§ Reliability
ī‚§ Redundancy
ī‚§ Failover
The 6 Resilience Layers
6.Facilities and Security
Level of the enterprise’s facilities:
īŽ Environment considerations
īŽ Geographical location
īŽ Dispersion
īŽ Security Access (Physical and logical security)
īŽ Power protection
īŽ Heating and cooling
The 6 Resilience Layers
Examples
1.

2.

3.

4.

5.

6.

Strategy
īŽ
The university position in comparison to others
Organization
īŽ
Executive support
Business and IT Processes
īŽ
IT Processes changing
Data and Applications
īŽ
SharePoint Server for all data – Diversification is required
Technology
īŽ
No additional Exchange or SharePoint server
Facilities and security
īŽ
Eminent power outage in case of disaster
Training for the DRP team
īŽ
īŽ
īŽ
īŽ
īŽ
īŽ
īŽ

Risk evaluation and control
Business impact analysis
Emergency response and operations
Incident management
Developing and implementing DRP/ECPs
Maintaining and exercising BCPs
Public relations, media and crisis communication
Choosing outside expertise to
assist with development of a DRP
Consultant that:
īŽ
Acts as a facilitator whenever it is appropriate
īŽ
Produces solid lasting solutions
īŽ
Understands and acts to further the client’s mission
īŽ
Only makes promises when they can be kept
īŽ
Minimizes dependency of the client on the consultant
īŽ
Encourages the client’s competence, confidence and commitment
īŽ
Works with the client on the problem solution
īŽ
Focuses on the relationship with the client and technical problems
īŽ
Doesn’t take on any of the client’s responsibilities.
Developing a DRP/ECP awareness
campaign
īŽ
īŽ
īŽ
īŽ

Establish goals and Components
Define the training/awareness method
Identify the target / audience
Implementing the awareness program
Implementing a DRP/ECP
awareness campaign
īŽ
īŽ
īŽ
īŽ
īŽ

Include DRP/ECP in the New Hire Orientation
Formal training
Awareness seminars and Brown bag sessions
Newsletter and Intranet
DRP/ECP quizzes
References
īŽ

īŽ

īŽ

īŽ

īŽ

īŽ

Hiles, A. (2007). The Definitive Handbook of Business Continuity
Management, Second Edition. John Wiley & Sons.
Hiles, A. (2011). The Definitive Handbook of Business Continuity
Management, Third Edition. John Wiley & Sons.
Goble, G., Fields, H., & Cocchiara, R. (2002). Resilient Infrastructure:
improving your business resilience. IBM Global Services.
Maiwald, E., & Sieglein, W. (2002). Security Planning & Disaster Recovery.
Berkeley, CA: McGraw-Hill/Osborne.
BS 25999-1 (2006). Business Continuity Management - Code of Practice.
BSI.
BS 25999-2 (2007). Business Continuity Management - Specification. BSI.

More Related Content

What's hot

Disaster Recovery Plan
Disaster Recovery Plan Disaster Recovery Plan
Disaster Recovery Plan Emilie Gray
 
IT-Centric Disaster Recovery & Business Continuity
IT-Centric Disaster Recovery & Business ContinuityIT-Centric Disaster Recovery & Business Continuity
IT-Centric Disaster Recovery & Business ContinuitySteve Susina
 
Disaster Recovery Plan
Disaster Recovery PlanDisaster Recovery Plan
Disaster Recovery Planmhdpaknejad
 
What is business continuity planning-bcp
What is business continuity planning-bcpWhat is business continuity planning-bcp
What is business continuity planning-bcpAdv Prashant Mali
 
Business continuity & Disaster recovery planing
Business continuity & Disaster recovery planingBusiness continuity & Disaster recovery planing
Business continuity & Disaster recovery planingHanaysha
 
Bcp
BcpBcp
Bcpmadunix
 
Building a Business Continuity Capability
Building a Business Continuity CapabilityBuilding a Business Continuity Capability
Building a Business Continuity CapabilityRod Davis
 
Disaster Recovery Planning PowerPoint Presentation Slides
Disaster Recovery Planning PowerPoint Presentation SlidesDisaster Recovery Planning PowerPoint Presentation Slides
Disaster Recovery Planning PowerPoint Presentation SlidesSlideTeam
 
Assess Your Business Continuity Management Process
Assess Your Business Continuity Management ProcessAssess Your Business Continuity Management Process
Assess Your Business Continuity Management ProcessAnand Subramaniam
 
Business Continuity Workshop Final
Business Continuity Workshop   FinalBusiness Continuity Workshop   Final
Business Continuity Workshop FinalBill Lisse
 
Disaster recovery solution
Disaster recovery solutionDisaster recovery solution
Disaster recovery solutionAnton An
 
Business continuity and disaster recovery
Business continuity and disaster recoveryBusiness continuity and disaster recovery
Business continuity and disaster recoveryAdeel Javaid
 
Bcm Roadmap
Bcm RoadmapBcm Roadmap
Bcm Roadmapbtrmuray
 
Information Technology Disaster Planning
Information Technology Disaster PlanningInformation Technology Disaster Planning
Information Technology Disaster Planningguest340570
 
Disaster Recovery Plan for IT
Disaster Recovery Plan for ITDisaster Recovery Plan for IT
Disaster Recovery Plan for IThhuihhui
 
Business Continuity - Business Risk & Management
Business Continuity - Business Risk & ManagementBusiness Continuity - Business Risk & Management
Business Continuity - Business Risk & ManagementAndrew Styles
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planningalanlund
 

What's hot (20)

Disaster Recovery Plan
Disaster Recovery Plan Disaster Recovery Plan
Disaster Recovery Plan
 
IT-Centric Disaster Recovery & Business Continuity
IT-Centric Disaster Recovery & Business ContinuityIT-Centric Disaster Recovery & Business Continuity
IT-Centric Disaster Recovery & Business Continuity
 
Disaster Recovery Plan
Disaster Recovery PlanDisaster Recovery Plan
Disaster Recovery Plan
 
009.itsecurity bcp v1
009.itsecurity bcp v1009.itsecurity bcp v1
009.itsecurity bcp v1
 
What is business continuity planning-bcp
What is business continuity planning-bcpWhat is business continuity planning-bcp
What is business continuity planning-bcp
 
Business continuity & Disaster recovery planing
Business continuity & Disaster recovery planingBusiness continuity & Disaster recovery planing
Business continuity & Disaster recovery planing
 
Bcp
BcpBcp
Bcp
 
Building a Business Continuity Capability
Building a Business Continuity CapabilityBuilding a Business Continuity Capability
Building a Business Continuity Capability
 
Business Continuity Planning Presentation
Business Continuity Planning PresentationBusiness Continuity Planning Presentation
Business Continuity Planning Presentation
 
Disaster Recovery Planning PowerPoint Presentation Slides
Disaster Recovery Planning PowerPoint Presentation SlidesDisaster Recovery Planning PowerPoint Presentation Slides
Disaster Recovery Planning PowerPoint Presentation Slides
 
Assess Your Business Continuity Management Process
Assess Your Business Continuity Management ProcessAssess Your Business Continuity Management Process
Assess Your Business Continuity Management Process
 
Business Continuity Workshop Final
Business Continuity Workshop   FinalBusiness Continuity Workshop   Final
Business Continuity Workshop Final
 
Disaster recovery solution
Disaster recovery solutionDisaster recovery solution
Disaster recovery solution
 
Business continuity and disaster recovery
Business continuity and disaster recoveryBusiness continuity and disaster recovery
Business continuity and disaster recovery
 
Disaster Recovery Plan
Disaster Recovery PlanDisaster Recovery Plan
Disaster Recovery Plan
 
Bcm Roadmap
Bcm RoadmapBcm Roadmap
Bcm Roadmap
 
Information Technology Disaster Planning
Information Technology Disaster PlanningInformation Technology Disaster Planning
Information Technology Disaster Planning
 
Disaster Recovery Plan for IT
Disaster Recovery Plan for ITDisaster Recovery Plan for IT
Disaster Recovery Plan for IT
 
Business Continuity - Business Risk & Management
Business Continuity - Business Risk & ManagementBusiness Continuity - Business Risk & Management
Business Continuity - Business Risk & Management
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 

Viewers also liked

Disaster Recovery Presentation
Disaster Recovery PresentationDisaster Recovery Presentation
Disaster Recovery PresentationTimSchaefer
 
The A to Z Guide to Business Continuity and Disaster Recovery
The A to Z Guide to Business Continuity and Disaster RecoveryThe A to Z Guide to Business Continuity and Disaster Recovery
The A to Z Guide to Business Continuity and Disaster RecoverySirius
 
Disaster Recovery & Data Backup Strategies
Disaster Recovery & Data Backup StrategiesDisaster Recovery & Data Backup Strategies
Disaster Recovery & Data Backup StrategiesSpiceworks
 
Business Continuity And Disaster Recovery Notes
Business Continuity And Disaster Recovery NotesBusiness Continuity And Disaster Recovery Notes
Business Continuity And Disaster Recovery NotesAlan McSweeney
 
DoS Attack - Incident Handling
DoS Attack - Incident HandlingDoS Attack - Incident Handling
DoS Attack - Incident HandlingMarcelo Silva
 
5 Things Every IT Disaster Recovery Plan Should Include
5 Things Every IT Disaster Recovery Plan Should Include5 Things Every IT Disaster Recovery Plan Should Include
5 Things Every IT Disaster Recovery Plan Should IncludeCWPS
 
Drp For Menora
Drp For MenoraDrp For Menora
Drp For MenoraPini Cohen
 
Disaster Recovery Plan
Disaster Recovery PlanDisaster Recovery Plan
Disaster Recovery PlanDavid Donovan
 
02 Practical Strategies of Conducting BIA
02 Practical Strategies of Conducting BIA02 Practical Strategies of Conducting BIA
02 Practical Strategies of Conducting BIABCM Institute
 
Business continuity planning and disaster recovery
Business continuity planning and disaster recoveryBusiness continuity planning and disaster recovery
Business continuity planning and disaster recoverymadunix
 
Assessment task 3 powerpoint presentation
Assessment task 3   powerpoint presentationAssessment task 3   powerpoint presentation
Assessment task 3 powerpoint presentationByron Polley
 
Why inspection?
Why inspection?Why inspection?
Why inspection?Saiko Shiroto
 
System Architecture v3.0
System Architecture v3.0System Architecture v3.0
System Architecture v3.0Jon Fortman
 
Introduction to the Enterprise Architecture Toolkit - Japanese
Introduction to the Enterprise Architecture Toolkit - JapaneseIntroduction to the Enterprise Architecture Toolkit - Japanese
Introduction to the Enterprise Architecture Toolkit - JapaneseMike Walker
 
Improving on How Architectures are Described
Improving on How Architectures are DescribedImproving on How Architectures are Described
Improving on How Architectures are DescribedMike Walker
 
Business Impact Analysis - The Most Important Step during BCMS Implementation
Business Impact Analysis - The Most Important Step during BCMS ImplementationBusiness Impact Analysis - The Most Important Step during BCMS Implementation
Business Impact Analysis - The Most Important Step during BCMS ImplementationPECB
 
BCI & Plan B DR best practice presentation 110914
BCI &  Plan B DR best practice presentation 110914BCI &  Plan B DR best practice presentation 110914
BCI & Plan B DR best practice presentation 110914Plan B Disaster Recovery Ltd
 
A Board Perspective on Enterprise Risk Management
A Board Perspective on Enterprise Risk ManagementA Board Perspective on Enterprise Risk Management
A Board Perspective on Enterprise Risk ManagementTurlough Guerin GAICD FGIA
 

Viewers also liked (19)

Disaster Recovery Presentation
Disaster Recovery PresentationDisaster Recovery Presentation
Disaster Recovery Presentation
 
The A to Z Guide to Business Continuity and Disaster Recovery
The A to Z Guide to Business Continuity and Disaster RecoveryThe A to Z Guide to Business Continuity and Disaster Recovery
The A to Z Guide to Business Continuity and Disaster Recovery
 
Disaster Recovery & Data Backup Strategies
Disaster Recovery & Data Backup StrategiesDisaster Recovery & Data Backup Strategies
Disaster Recovery & Data Backup Strategies
 
Business Continuity And Disaster Recovery Notes
Business Continuity And Disaster Recovery NotesBusiness Continuity And Disaster Recovery Notes
Business Continuity And Disaster Recovery Notes
 
Butler
ButlerButler
Butler
 
DoS Attack - Incident Handling
DoS Attack - Incident HandlingDoS Attack - Incident Handling
DoS Attack - Incident Handling
 
5 Things Every IT Disaster Recovery Plan Should Include
5 Things Every IT Disaster Recovery Plan Should Include5 Things Every IT Disaster Recovery Plan Should Include
5 Things Every IT Disaster Recovery Plan Should Include
 
Drp For Menora
Drp For MenoraDrp For Menora
Drp For Menora
 
Disaster Recovery Plan
Disaster Recovery PlanDisaster Recovery Plan
Disaster Recovery Plan
 
02 Practical Strategies of Conducting BIA
02 Practical Strategies of Conducting BIA02 Practical Strategies of Conducting BIA
02 Practical Strategies of Conducting BIA
 
Business continuity planning and disaster recovery
Business continuity planning and disaster recoveryBusiness continuity planning and disaster recovery
Business continuity planning and disaster recovery
 
Assessment task 3 powerpoint presentation
Assessment task 3   powerpoint presentationAssessment task 3   powerpoint presentation
Assessment task 3 powerpoint presentation
 
Why inspection?
Why inspection?Why inspection?
Why inspection?
 
System Architecture v3.0
System Architecture v3.0System Architecture v3.0
System Architecture v3.0
 
Introduction to the Enterprise Architecture Toolkit - Japanese
Introduction to the Enterprise Architecture Toolkit - JapaneseIntroduction to the Enterprise Architecture Toolkit - Japanese
Introduction to the Enterprise Architecture Toolkit - Japanese
 
Improving on How Architectures are Described
Improving on How Architectures are DescribedImproving on How Architectures are Described
Improving on How Architectures are Described
 
Business Impact Analysis - The Most Important Step during BCMS Implementation
Business Impact Analysis - The Most Important Step during BCMS ImplementationBusiness Impact Analysis - The Most Important Step during BCMS Implementation
Business Impact Analysis - The Most Important Step during BCMS Implementation
 
BCI & Plan B DR best practice presentation 110914
BCI &  Plan B DR best practice presentation 110914BCI &  Plan B DR best practice presentation 110914
BCI & Plan B DR best practice presentation 110914
 
A Board Perspective on Enterprise Risk Management
A Board Perspective on Enterprise Risk ManagementA Board Perspective on Enterprise Risk Management
A Board Perspective on Enterprise Risk Management
 

Similar to Disaster Recovery Plan / Enterprise Continuity Plan

Integrating Resiliency As A Strategic Priority
Integrating Resiliency As A Strategic PriorityIntegrating Resiliency As A Strategic Priority
Integrating Resiliency As A Strategic PriorityGeoff Rodrigues
 
Integrating Resiliency As A Strategic Priority
Integrating Resiliency As A Strategic PriorityIntegrating Resiliency As A Strategic Priority
Integrating Resiliency As A Strategic PriorityGeoff Rodrigues
 
Product Management And Service Delivery Process - FlackVentures Example
Product Management And Service Delivery Process - FlackVentures ExampleProduct Management And Service Delivery Process - FlackVentures Example
Product Management And Service Delivery Process - FlackVentures ExampleKate Pynn
 
CERTIFIED INFORMATION TECHNOLOGY MANAGER
CERTIFIED INFORMATION TECHNOLOGY MANAGERCERTIFIED INFORMATION TECHNOLOGY MANAGER
CERTIFIED INFORMATION TECHNOLOGY MANAGERDee Smith & Associates
 
Risk Leadership Perspectives Breakfast Risk Manager of the Year Karl Davey
Risk Leadership Perspectives Breakfast Risk Manager of the Year Karl DaveyRisk Leadership Perspectives Breakfast Risk Manager of the Year Karl Davey
Risk Leadership Perspectives Breakfast Risk Manager of the Year Karl Daveykarld
 
Data analysis and interpretation flyer
Data analysis and interpretation flyerData analysis and interpretation flyer
Data analysis and interpretation flyerKALVI World
 
Orlando SFDC User Group 8/2009
Orlando SFDC User Group 8/2009Orlando SFDC User Group 8/2009
Orlando SFDC User Group 8/2009Joshua Hoskins
 
Do data leaders face unique challenges as leaders?
Do data leaders face unique challenges as leaders?Do data leaders face unique challenges as leaders?
Do data leaders face unique challenges as leaders?Paul Laughlin
 
Business Analytics
Business AnalyticsBusiness Analytics
Business AnalyticsPrem Anand
 
110430 bcm presentation v0.1 mj
110430 bcm presentation v0.1 mj110430 bcm presentation v0.1 mj
110430 bcm presentation v0.1 mjMike Jackson - LION
 
Enterprise Content Management (ECM) System
Enterprise Content Management (ECM) SystemEnterprise Content Management (ECM) System
Enterprise Content Management (ECM) SystemAnand Subramaniam
 
CRM Training and Simulation Programs ASCI 516Module 7 Presen.docx
CRM Training and Simulation Programs ASCI 516Module 7 Presen.docxCRM Training and Simulation Programs ASCI 516Module 7 Presen.docx
CRM Training and Simulation Programs ASCI 516Module 7 Presen.docxmydrynan
 
Feb2008 Service Desk Maturity Models & Fram
Feb2008 Service Desk Maturity Models & FramFeb2008 Service Desk Maturity Models & Fram
Feb2008 Service Desk Maturity Models & FramIT Service and Support
 
TalentGuider - Capability Development in Pharma functions
TalentGuider - Capability Development in Pharma functionsTalentGuider - Capability Development in Pharma functions
TalentGuider - Capability Development in Pharma functionsMarkus Moravek
 
4 Steps To Boost Agent Productivity
4 Steps To Boost Agent Productivity4 Steps To Boost Agent Productivity
4 Steps To Boost Agent ProductivityNicolas Rodriguez
 
4 Strategies To Boost Agent Productivity
4 Strategies To Boost Agent Productivity4 Strategies To Boost Agent Productivity
4 Strategies To Boost Agent ProductivityAggregage
 
Talent Management
Talent Management Talent Management
Talent Management Doug Young
 
TCG Svcs Pres 2011
TCG Svcs Pres 2011TCG Svcs Pres 2011
TCG Svcs Pres 2011mcourton
 
The State of Project Portfolio Management August, 2013
The State of Project Portfolio Management   August, 2013The State of Project Portfolio Management   August, 2013
The State of Project Portfolio Management August, 2013EclipseProjectPortfolioManagement
 
Quo Vadis & Antal Linkedin Oct 08
Quo Vadis & Antal Linkedin Oct 08Quo Vadis & Antal Linkedin Oct 08
Quo Vadis & Antal Linkedin Oct 08QuoVadisC
 

Similar to Disaster Recovery Plan / Enterprise Continuity Plan (20)

Integrating Resiliency As A Strategic Priority
Integrating Resiliency As A Strategic PriorityIntegrating Resiliency As A Strategic Priority
Integrating Resiliency As A Strategic Priority
 
Integrating Resiliency As A Strategic Priority
Integrating Resiliency As A Strategic PriorityIntegrating Resiliency As A Strategic Priority
Integrating Resiliency As A Strategic Priority
 
Product Management And Service Delivery Process - FlackVentures Example
Product Management And Service Delivery Process - FlackVentures ExampleProduct Management And Service Delivery Process - FlackVentures Example
Product Management And Service Delivery Process - FlackVentures Example
 
CERTIFIED INFORMATION TECHNOLOGY MANAGER
CERTIFIED INFORMATION TECHNOLOGY MANAGERCERTIFIED INFORMATION TECHNOLOGY MANAGER
CERTIFIED INFORMATION TECHNOLOGY MANAGER
 
Risk Leadership Perspectives Breakfast Risk Manager of the Year Karl Davey
Risk Leadership Perspectives Breakfast Risk Manager of the Year Karl DaveyRisk Leadership Perspectives Breakfast Risk Manager of the Year Karl Davey
Risk Leadership Perspectives Breakfast Risk Manager of the Year Karl Davey
 
Data analysis and interpretation flyer
Data analysis and interpretation flyerData analysis and interpretation flyer
Data analysis and interpretation flyer
 
Orlando SFDC User Group 8/2009
Orlando SFDC User Group 8/2009Orlando SFDC User Group 8/2009
Orlando SFDC User Group 8/2009
 
Do data leaders face unique challenges as leaders?
Do data leaders face unique challenges as leaders?Do data leaders face unique challenges as leaders?
Do data leaders face unique challenges as leaders?
 
Business Analytics
Business AnalyticsBusiness Analytics
Business Analytics
 
110430 bcm presentation v0.1 mj
110430 bcm presentation v0.1 mj110430 bcm presentation v0.1 mj
110430 bcm presentation v0.1 mj
 
Enterprise Content Management (ECM) System
Enterprise Content Management (ECM) SystemEnterprise Content Management (ECM) System
Enterprise Content Management (ECM) System
 
CRM Training and Simulation Programs ASCI 516Module 7 Presen.docx
CRM Training and Simulation Programs ASCI 516Module 7 Presen.docxCRM Training and Simulation Programs ASCI 516Module 7 Presen.docx
CRM Training and Simulation Programs ASCI 516Module 7 Presen.docx
 
Feb2008 Service Desk Maturity Models & Fram
Feb2008 Service Desk Maturity Models & FramFeb2008 Service Desk Maturity Models & Fram
Feb2008 Service Desk Maturity Models & Fram
 
TalentGuider - Capability Development in Pharma functions
TalentGuider - Capability Development in Pharma functionsTalentGuider - Capability Development in Pharma functions
TalentGuider - Capability Development in Pharma functions
 
4 Steps To Boost Agent Productivity
4 Steps To Boost Agent Productivity4 Steps To Boost Agent Productivity
4 Steps To Boost Agent Productivity
 
4 Strategies To Boost Agent Productivity
4 Strategies To Boost Agent Productivity4 Strategies To Boost Agent Productivity
4 Strategies To Boost Agent Productivity
 
Talent Management
Talent Management Talent Management
Talent Management
 
TCG Svcs Pres 2011
TCG Svcs Pres 2011TCG Svcs Pres 2011
TCG Svcs Pres 2011
 
The State of Project Portfolio Management August, 2013
The State of Project Portfolio Management   August, 2013The State of Project Portfolio Management   August, 2013
The State of Project Portfolio Management August, 2013
 
Quo Vadis & Antal Linkedin Oct 08
Quo Vadis & Antal Linkedin Oct 08Quo Vadis & Antal Linkedin Oct 08
Quo Vadis & Antal Linkedin Oct 08
 

Recently uploaded

7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...Paul Menig
 
Call Girls in Mehrauli Delhi đŸ’¯Call Us 🔝8264348440🔝
Call Girls in Mehrauli Delhi đŸ’¯Call Us 🔝8264348440🔝Call Girls in Mehrauli Delhi đŸ’¯Call Us 🔝8264348440🔝
Call Girls in Mehrauli Delhi đŸ’¯Call Us 🔝8264348440🔝soniya singh
 
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfpollardmorgan
 
Cash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call GirlsCash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call GirlsApsara Of India
 
Eni 2024 1Q Results - 24.04.24 business.
Eni 2024 1Q Results - 24.04.24 business.Eni 2024 1Q Results - 24.04.24 business.
Eni 2024 1Q Results - 24.04.24 business.Eni
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Serviceritikaroy0888
 
Non Text Magic Studio Magic Design for Presentations L&P.pptx
Non Text Magic Studio Magic Design for Presentations L&P.pptxNon Text Magic Studio Magic Design for Presentations L&P.pptx
Non Text Magic Studio Magic Design for Presentations L&P.pptxAbhayThakur200703
 
Sales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessSales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessAggregage
 
VIP Call Girls Pune Kirti 8617697112 Independent Escort Service Pune
VIP Call Girls Pune Kirti 8617697112 Independent Escort Service PuneVIP Call Girls Pune Kirti 8617697112 Independent Escort Service Pune
VIP Call Girls Pune Kirti 8617697112 Independent Escort Service PuneCall girls in Ahmedabad High profile
 
Monte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMMonte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMRavindra Nath Shukla
 
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
Tech Startup Growth Hacking 101  - Basics on Growth MarketingTech Startup Growth Hacking 101  - Basics on Growth Marketing
Tech Startup Growth Hacking 101 - Basics on Growth MarketingShawn Pang
 
rishikeshgirls.in- Rishikesh call girl.pdf
rishikeshgirls.in- Rishikesh call girl.pdfrishikeshgirls.in- Rishikesh call girl.pdf
rishikeshgirls.in- Rishikesh call girl.pdfmuskan1121w
 
Call Girls In Sikandarpur Gurgaon ❤ī¸8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤ī¸8860477959_Russian 100% Genuine Escorts I...Call Girls In Sikandarpur Gurgaon ❤ī¸8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤ī¸8860477959_Russian 100% Genuine Escorts I...lizamodels9
 
Regression analysis: Simple Linear Regression Multiple Linear Regression
Regression analysis:  Simple Linear Regression Multiple Linear RegressionRegression analysis:  Simple Linear Regression Multiple Linear Regression
Regression analysis: Simple Linear Regression Multiple Linear RegressionRavindra Nath Shukla
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999Tina Ji
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Neil Kimberley
 
Call Girls In Sikandarpur Gurgaon ❤ī¸8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤ī¸8860477959_Russian 100% Genuine Escorts I...Call Girls In Sikandarpur Gurgaon ❤ī¸8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤ī¸8860477959_Russian 100% Genuine Escorts I...lizamodels9
 
Call Girls In Connaught Place Delhi ❤ī¸88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤ī¸88604**77959_Russian 100% Genuine Escor...Call Girls In Connaught Place Delhi ❤ī¸88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤ī¸88604**77959_Russian 100% Genuine Escor...lizamodels9
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMANIlamathiKannappan
 

Recently uploaded (20)

7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...
 
Call Girls in Mehrauli Delhi đŸ’¯Call Us 🔝8264348440🔝
Call Girls in Mehrauli Delhi đŸ’¯Call Us 🔝8264348440🔝Call Girls in Mehrauli Delhi đŸ’¯Call Us 🔝8264348440🔝
Call Girls in Mehrauli Delhi đŸ’¯Call Us 🔝8264348440🔝
 
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
 
Cash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call GirlsCash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call Girls
 
Eni 2024 1Q Results - 24.04.24 business.
Eni 2024 1Q Results - 24.04.24 business.Eni 2024 1Q Results - 24.04.24 business.
Eni 2024 1Q Results - 24.04.24 business.
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Service
 
Non Text Magic Studio Magic Design for Presentations L&P.pptx
Non Text Magic Studio Magic Design for Presentations L&P.pptxNon Text Magic Studio Magic Design for Presentations L&P.pptx
Non Text Magic Studio Magic Design for Presentations L&P.pptx
 
Sales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessSales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for Success
 
VIP Call Girls Pune Kirti 8617697112 Independent Escort Service Pune
VIP Call Girls Pune Kirti 8617697112 Independent Escort Service PuneVIP Call Girls Pune Kirti 8617697112 Independent Escort Service Pune
VIP Call Girls Pune Kirti 8617697112 Independent Escort Service Pune
 
Monte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMMonte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSM
 
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
Tech Startup Growth Hacking 101  - Basics on Growth MarketingTech Startup Growth Hacking 101  - Basics on Growth Marketing
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
 
rishikeshgirls.in- Rishikesh call girl.pdf
rishikeshgirls.in- Rishikesh call girl.pdfrishikeshgirls.in- Rishikesh call girl.pdf
rishikeshgirls.in- Rishikesh call girl.pdf
 
Call Girls In Sikandarpur Gurgaon ❤ī¸8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤ī¸8860477959_Russian 100% Genuine Escorts I...Call Girls In Sikandarpur Gurgaon ❤ī¸8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤ī¸8860477959_Russian 100% Genuine Escorts I...
 
Regression analysis: Simple Linear Regression Multiple Linear Regression
Regression analysis:  Simple Linear Regression Multiple Linear RegressionRegression analysis:  Simple Linear Regression Multiple Linear Regression
Regression analysis: Simple Linear Regression Multiple Linear Regression
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
 
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
Russian Faridabad Call Girls(Badarpur) : ☎ 8168257667, @4999
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023
 
Call Girls In Sikandarpur Gurgaon ❤ī¸8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤ī¸8860477959_Russian 100% Genuine Escorts I...Call Girls In Sikandarpur Gurgaon ❤ī¸8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤ī¸8860477959_Russian 100% Genuine Escorts I...
 
Call Girls In Connaught Place Delhi ❤ī¸88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤ī¸88604**77959_Russian 100% Genuine Escor...Call Girls In Connaught Place Delhi ❤ī¸88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤ī¸88604**77959_Russian 100% Genuine Escor...
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMAN
 

Disaster Recovery Plan / Enterprise Continuity Plan

  • 1. DRP/ECP Disaster Recovery Plan / Enterprise Continuity Plan Marcelo Silva
  • 2. Agenda īŽ īŽ īŽ īŽ īŽ īŽ īŽ Introduction Roles of DRP/ECP The 6 Resilience Layers Training for the DRP team Choosing outside expertise to assist with development of a DRP Developing a DRP/ECP awareness campaign Implementing a DRP/ECP awareness campaign
  • 3. Introduction īŽ īŽ īŽ īŽ Why DRP/ECP? Benefits of a DRP/ECP Three vital Ingredients of a successful DRP/ECP Defensive Posture / Offensive Posture
  • 4. Roles of DRP/ECP īŽ īŽ īŽ īŽ īŽ īŽ īŽ Emergency Management team (EMT) Damage Assessment Team Restoration Team Operations Team Customer Support Team Salvage/Reclamation Team Administrative Support Team
  • 5. The 6 Resilience Layers 1. 2. 3. 4. 5. 6. Strategy Organization Business and IT Processes Data and Applications Technology Facilities and security
  • 6. The 6 Resilience Layers 1.Strategy Strategy is the first layer to be discussed On this layer, the below components will be assessed and examined: īŽ Vulnerabilities īŽ Risks īŽ Competitive edge īŽ baseline organizational culture
  • 7. The 6 Resilience Layers 2.Organization īŽ īŽ īŽ īŽ īŽ Executive sponsor Roles, Responsibilities and Accountabilities Well defined communication protocol Cross-line-of-business linkage Skills that are critical to the company
  • 8. The 6 Resilience Layers 3.Business and IT Process A successful plan requires identify: īŽ īŽ īŽ īŽ īŽ The minimum required functionalities during disruptive events Alternate process/procedure that will allow operations to continue Processes to achieve better workload balance All processes and the contingency plan must be clear to all organization’s stakeholders Business processes that support Virtual, flexible and distributed workplaces
  • 9. The 6 Resilience Layers 4.Data and Applications īŽ īŽ īŽ īŽ Good, valuable and reliable information Data and Application diversification Architectures standardization Ensure performance, availability and scalability
  • 10. The 6 Resilience Layers 5.Technology Technology components when planning resiliency: īŽ Hardware architecture īŽ System software īŽ Middleware īŽ Networks īŽ Security Solutions Levels of availability that should be aligned to the resiliency objectives: ī‚§ Reliability ī‚§ Redundancy ī‚§ Failover
  • 11. The 6 Resilience Layers 6.Facilities and Security Level of the enterprise’s facilities: īŽ Environment considerations īŽ Geographical location īŽ Dispersion īŽ Security Access (Physical and logical security) īŽ Power protection īŽ Heating and cooling
  • 12. The 6 Resilience Layers Examples 1. 2. 3. 4. 5. 6. Strategy īŽ The university position in comparison to others Organization īŽ Executive support Business and IT Processes īŽ IT Processes changing Data and Applications īŽ SharePoint Server for all data – Diversification is required Technology īŽ No additional Exchange or SharePoint server Facilities and security īŽ Eminent power outage in case of disaster
  • 13. Training for the DRP team īŽ īŽ īŽ īŽ īŽ īŽ īŽ Risk evaluation and control Business impact analysis Emergency response and operations Incident management Developing and implementing DRP/ECPs Maintaining and exercising BCPs Public relations, media and crisis communication
  • 14. Choosing outside expertise to assist with development of a DRP Consultant that: īŽ Acts as a facilitator whenever it is appropriate īŽ Produces solid lasting solutions īŽ Understands and acts to further the client’s mission īŽ Only makes promises when they can be kept īŽ Minimizes dependency of the client on the consultant īŽ Encourages the client’s competence, confidence and commitment īŽ Works with the client on the problem solution īŽ Focuses on the relationship with the client and technical problems īŽ Doesn’t take on any of the client’s responsibilities.
  • 15. Developing a DRP/ECP awareness campaign īŽ īŽ īŽ īŽ Establish goals and Components Define the training/awareness method Identify the target / audience Implementing the awareness program
  • 16. Implementing a DRP/ECP awareness campaign īŽ īŽ īŽ īŽ īŽ Include DRP/ECP in the New Hire Orientation Formal training Awareness seminars and Brown bag sessions Newsletter and Intranet DRP/ECP quizzes
  • 17. References īŽ īŽ īŽ īŽ īŽ īŽ Hiles, A. (2007). The Definitive Handbook of Business Continuity Management, Second Edition. John Wiley & Sons. Hiles, A. (2011). The Definitive Handbook of Business Continuity Management, Third Edition. John Wiley & Sons. Goble, G., Fields, H., & Cocchiara, R. (2002). Resilient Infrastructure: improving your business resilience. IBM Global Services. Maiwald, E., & Sieglein, W. (2002). Security Planning & Disaster Recovery. Berkeley, CA: McGraw-Hill/Osborne. BS 25999-1 (2006). Business Continuity Management - Code of Practice. BSI. BS 25999-2 (2007). Business Continuity Management - Specification. BSI.

Editor's Notes

  1. Western Governors UniversityMaster of Science, Information Security and AssuranceFXT2 – Disaster Recovery Planning, Prevention and ResponseMarcelo Braga SilvaStudent ID: 000200452
  2. This Agenda will cover the requirements for the Task 1 of the FXT2 course, part of the Master of Science, Information Security and Assurance program at WGU.January, 2014.
  3. According to Goble, Fields, & Cocchiara (2002), resilient infrastructures are those ones that are “capable of proactively responding to both anticipated and unexpected stress and strains” (p. 2).Thus, following below an introduction on the Disaster recovery Plan and Enterprise Continuity Plan:Why DRP/ECP?In case some infrastructure failure, if the university is not well prepared to respond to such unexpected event, it can lose some business opportunities, students and partners, reputation and credibility, research data, and even its most valuable information and applications.Benefits of a DRP/ECPIdentification of critical applications and services for the businessIdentification and preparedness for the major risksReduce the downtimes of applications and services Improve operational effectiveness and resilienceProtection of assetsBe compliance with national and international laws and standardsImprove securityDemonstrate continuity capabilities for the market, including customers, partners and shareholdersThree vital Ingredients of a successful DRP/ECP (Goble, G., Fields, H., & Cocchiara, R. 2002, p. 9)Recovery īƒ  Safe, rapid, offsite data recoveryHardening īƒ  The fortification of all or part of the infrastructureRedundancy īƒ  The duplication of all or part of the infrastructure Defensive Posture / Offensive PostureDefensive Posture components:Recovery Hardening Redundancy Offensive Posture components:AccessibilityDiversificationAutonomic computing
  4. The DRP/ECP team are composed by different teams. One of the key teams is the Emergency Management Team (EMT)According to Hiles (2007), the EMT’s role is “to take business decisions, assess and make judgments on business priorities and to facilitate and support the business continuity manager. It also has an important role in marketing, public relations and media management issues.”Following below some roles of the DRP/ECP team members:Emergency Management Team Composed by key senior managers, Public relations and marketing and Business continuity manager or coordinator.Damage Assessment TeamThe Damage Assessment Team assesses the damage to the Data Center and reports to the EMT.Restoration TeamThis team brings the Production site systems and applications to operational mode in a DR site. And also brings they back to the production site.Operations TeamThe Operations Team assists in the recovery operations of infrastructure, systems and services.Customer Support TeamThis is the team that assists the customers (external/internal) during the disaster, until operations are resumed.Salvage/Reclamation TeamThe Salvage/Reclamation Team manages the restoration or rebuilding of the Data Center.Administrative Support TeamThe Administrative Support Team cooperate with logistical and organizational support for all other teams.
  5. This six layers represent the “Framework for resiliency” (Goble, Fields, & Cocchiara, 2002).This framework enables management and technical teams to lead the Enterprise to a successful Disaster Recovery Plan.
  6. When we talk about preparedness for anticipated and unexpected events, the Strategy layer is the first one to be discussed. On this layer, some assessments will examine components such as vulnerabilities and risks regarding to the enterprise, taking in account its industry position and its competitively. Also, the enterprise’s strategies and the baseline organizational culture will be examined. (Goble, Fields, & Cocchiara, 2002)
  7. Organizational changes are required to build a successful resiliency plan.It requires an Executive sponsor, usually a senior business leader or a Vice President.Roles, Responsibilities and AccountabilitiesWell defined communication protocolCross-line-of-business linkageSkills that are critical to the company
  8. The resiliency plan should focus on the business and IT process and procedures that are critical for the organization’s operation and its infrastructure. A successful plan requires identify:What are the minimum required functionalities during disruptive eventsAlternate process and procedure that will allow operations to continueProcesses to achieve better workload balanceAll processes and the contingency plan must be clear to all organization’s stakeholdersBusiness processes that support Virtual, flexible and distributed workplaces. (Goble, Fields, & Cocchiara, 2002).
  9. 21st Century organizations rely on good, valuable and reliable information, whether they are about customers, employees, competitors, products or suppliers, and the systems responsible for processing and analysing those information as well. Thus, multiples data and application sources are required. Data and Application diversificationArchitectures standardizationEnsure performance, availability and scalability
  10. Technology is a key component to create a resilient business. The IT infrastructure and the budget assigned to it must be aligned to the organization’s resiliency goals.Technology components when planning resiliency:Hardware architectureSystem softwareMiddlewareNetworksSecurity Solutions Levels of availability that should be aligned to the resiliency objectives:ReliabilityRedundancyFailoverSingle point of failure: Should be known and addressedHigh-Availability (HA) components in the infrastructure should be examined.Continuous replication across different sites (Primary/Secondary)
  11. When examining the resiliency level of the enterprise’s facilities:Environment considerationsGeographical locationDispersionSecurity Access (Physical and logical security)Power protection (UPS, batteries, Generators, etc.)Heating and cooling (Pods, Racks, small rooms, UPS rooms)Provide and testing the security mechanisms and equipment.
  12. Strategy: Risks, Vulnerabilities and competitively will be assessed, taking in account the position the university has in comparison to the other universities, regional and national.Organization: The university needs a executive support for the plan, and for all organizational changes that the university will need for a successful DRP.Business and IT Processes: The university will have to change some IT process in order to enable employees and students to leverage the university’s infrastructure beyond of the three-floor facilities that it has currently.Data and Applications: Currently the university uses the Microsoft SharePoint for all data. However, for a good resilient plan, some diversification of data and application should be implemented, and high availability by implementing redundant servers across different sites also recommended.Technology: The university has only one server for each application: One Exchange Server and one SharePoint Server. Currently there is no redundancy neither additional servers for failover in case of disaster, or even to recover from a simple hardware failure. Thus, there is a single point of failure and it’s something that will be addressed in the technology layer of the Framework for Resiliency.Facilities: There are physical risks to the operations. Blizzards could potentially knock out power and earthquakes could damage the building.
  13. BS 25999-1 (2006) requires that “the organization should have a process for identifying and delivering the BCM awareness requirements of the organization and evaluating the effectiveness of its delivery.”Risk evaluation and controlBusiness impact analysisEmergency response and operationsIncident managementDeveloping and implementing DRP/ECPsMaintaining and exercising BCPsPublic relations, media and crisis communication
  14. The university should look for the following characteristics on outside expertise to assist with the development of a DRP:Acts as a facilitator whenever it is appropriateAvoids “quick fixes” and produces solid lasting solutionsUnderstands and acts to further the client’s missionDoes not confuse the client by talking in a different languageOnly makes promises when they can be keptKeeps a good relationship with others in the companyMinimizes dependency of the client on the consultantEncourages the client’s competence, confidence and commitmentWorks with the client on the problem solutionFocuses on the relationship with the client and technical problemsDoesn’t take on any of the client’s responsibilities.Hiles, A. (2007).
  15. BSI 25999-1 Business Continuity Management Code of Practice requires that “the organization should have a process for identifying and delivering the BCM awareness requirements of the organization and evaluating the effectiveness of its delivery.” (Hiles, 2011)Establish goals and ComponentsTraining the team leaders (“Train the trainers”) and other team membersCover the skills gaps in the Enterprise Continuity team, indicated in BS 25999/DRII Common Body of KnowledgeTrain the EC team through exercising the plan (Hiles, 2011).Disseminate all information related to the Disaster Recovery Plan and Enterprise Continuity Plan and Policy, including priorities and objectives, deliverables, level of acceptance of disruption and recovery time.Define the training/awareness methodInduction training for new hiresArticles, news and letters in corporate newslettersUse of internal web pages, blogs and Intranet.Conducting tests and exercises, with observersIdentify the target / audienceAll stakeholders: members of the Business Continuity team and other enterprise staff (Employees, contractors and consultants).Implementing the awareness program (next slide)
  16. Maiwald & Sieglein (2002) stated that we “should take advantage of every possible method to keep users interested and engaged”. Therefore, following below some training methods to be implemented as part of the DRP/ECP awareness campaign:Include DRP/ECP in the New Hire OrientationThe organization’s information security policies and procedures should be covered during the Orientation (Maiwald & Sieglein, 2002)The new hires should be compliant with all security policies and proceduresThe new hires should read and sign the Acceptable Use Policy and any other document related to the Information SecurityFormal trainingVendor’s specific training for the infrastructure and security teams: Network devices (Switches, routers, load balancers, gateways); Security solutions (Firewalls, proxies, IDS, IPS, Antivirus, HSMs); Servers (hardware, Operating Systems, Virtualization) among others.Internal training in accordance with each stakeholders group.Awareness seminars and Brown bag sessionsProvide information about new technologies within the company and the security related to themProvide the latest and useful information regards the DRP/ECPTell them how they can help in case of some unexpected event comes upExplain how the company is counting on them to have a successful DRP/ECP implementedNewsletter and IntranetImplement a quarterly Awareness Newsletter for end-usersCreate an area in the company Intranet dedicated to the DRP/ECP awarenessAdd some security-related information, including external links to vendor’s website and articlesDRP/ECP quizzesPeriodically enable some quizzes in the Intranet and also during some seminars and trainings, and promote some raffles as an way to encourage them.